Your message dated Sun, 31 Dec 2023 22:02:27 +0000
with message-id <[email protected]>
and subject line Bug#1059450: fixed in libspreadsheet-parseexcel-perl
0.6500-1.1+deb11u1
has caused the Debian Bug report #1059450,
regarding libspreadsheet-parseexcel-perl: CVE-2023-7101
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1059450: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059450
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libspreadsheet-parseexcel-perl
Version: 0.6500-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 0.6500-1.1
Control: found -1 0.6500-1
Control: affects -1 + libspreadsheet-parsexlsx-perl
Hi,
The following vulnerability was published for libspreadsheet-parseexcel-perl.
The writeup[2] contains a descrption of the issue and pocs. Note that
the issue in Spreadsheet::ParseExcel will affect as well
Spreadsheet::ParseXLSX relying on Spreadsheet::ParseExcel but AFAIU,
the issue needs to be fixed in Spreadsheet::ParseExcel.
CVE-2023-7101[0]:
| Spreadsheet::ParseExcel version 0.65 is a Perl module used for
| parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an
| arbitrary code execution (ACE) vulnerability due to passing
| unvalidated input from a file into a string-type “eval”.
| Specifically, the issue stems from the evaluation of Number format
| strings (not to be confused with printf-style format strings) within
| the Excel parsing logic.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2023-7101
https://www.cve.org/CVERecord?id=CVE-2023-7101
[1] https://github.com/haile01/perl_spreadsheet_excel_rce_poc
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libspreadsheet-parseexcel-perl
Source-Version: 0.6500-1.1+deb11u1
Done: Salvatore Bonaccorso <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libspreadsheet-parseexcel-perl, which is due to be installed in the Debian FTP
archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated
libspreadsheet-parseexcel-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 30 Dec 2023 13:59:46 +0100
Source: libspreadsheet-parseexcel-perl
Architecture: source
Version: 0.6500-1.1+deb11u1
Distribution: bullseye-security
Urgency: high
Maintainer: Debian Perl Group <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1059450
Changes:
libspreadsheet-parseexcel-perl (0.6500-1.1+deb11u1) bullseye-security;
urgency=high
.
* Team upload.
* Do not use string eval for conditional formatting (CVE-2023-7101)
(Closes: #1059450)
Checksums-Sha1:
ba50067717846b99a5edfc705d92c7c9b8bc266a 2717
libspreadsheet-parseexcel-perl_0.6500-1.1+deb11u1.dsc
22b496315035fe469f618f8e32f8f3e6e9c4b58a 6704
libspreadsheet-parseexcel-perl_0.6500-1.1+deb11u1.debian.tar.xz
Checksums-Sha256:
30167d1cfe9c764c99a3ad4d06012a7c0731ecac09e8e57895b659586fa617be 2717
libspreadsheet-parseexcel-perl_0.6500-1.1+deb11u1.dsc
be919c6b131044c1c62828bea3fb3da09cdf80285c858e14c68b6523c29292a8 6704
libspreadsheet-parseexcel-perl_0.6500-1.1+deb11u1.debian.tar.xz
Files:
eead8134d4cbe374d7795f5779646196 2717 perl optional
libspreadsheet-parseexcel-perl_0.6500-1.1+deb11u1.dsc
32aa4a2a9dd04fdfb9399631b65a8d66 6704 perl optional
libspreadsheet-parseexcel-perl_0.6500-1.1+deb11u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmWQFTVfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EcQMQAIJsFVPebU3Uq2kcdYrMY3m8xuqlee5k
wcNMAhCfvr6t6z6L6NuNw0uvo6SIKOmhHHRr87pDWZvNFeQbaWw+GRmaptCjNV/u
3ypPrJh1mPbVGIK1KEtN/dTx5PTLgas5Nye373aVs+l1Q8wefNdoX83nWvXp/6p/
D8I8Z3x8MsSmaCtk6STb66yjWuK8ijCnWSz1CMqq/acnlDfL9Bd6EPcXHnJWU6rr
a/fOACqVCcxbbBlxP3UNQ3RFISEexwQGT9HXaQzccnt44F3VRI2T2XDJV1Rn7+OA
SGMSwzAVZWAMw4bMHcHPluYWPuJ/gP4qctXeR4a0BYgsovUSRo4dmaRsOwEJsKR5
ce3Hqbm44pkodYm0eqA+uAxmdqs1x+cRbR0lJUp6i1HTJLs/CsDVnrtv1On2sMEQ
Y97Sm6ISN29vTirTBGXFaxAIRyFTsu54+JJkiFhgEHU9Y+NIDtHCwFhmpAod7Mts
+ntan9xUtA6X1v9SfrcKen2t03DNfCUSZkP4vSTSDC0dn+be9zWtqtfoQiX/veWz
EsKM5dbSl31lSfkmvNZir0pTMyKhpomI0mWlW9JgROIyfIjTs6aRG+sBTVCel9xc
7nUGXGz+Sx4IRgry3kBCK1cNt63a9K5LJXYYnmhhtb4++If9pajiJ2JHgzxydMva
stztrFhlGvuy
=iwjA
-----END PGP SIGNATURE-----
--- End Message ---